Cryptography & PKI Flashcards
7 cards from real SSCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography & PKI flashcards as text
Which cryptographic algorithm uses the same key for both encryption and decryption?
Answer: AES
AES (Advanced Encryption Standard) is a symmetric algorithm, meaning it uses the same secret key for both encrypting and decrypting data.
What is the primary role of a Certificate Authority (CA) in a PKI infrastructure?
Answer: Issuing and digitally signing digital certificates to validate identities
A Certificate Authority issues and signs digital certificates, binding a public key to an entity's identity, which is the foundational trust anchor in PKI.
Which property of a cryptographic hash function ensures that two different inputs cannot produce the same hash output?
Answer: Collision resistance
Collision resistance means it is computationally infeasible to find two distinct inputs that produce the same hash digest, preventing forgery of signed data.
In asymmetric cryptography, which key is used to verify a digital signature?
Answer: The signer's public key
A digital signature is created with the signer's private key and verified using the corresponding public key, confirming authenticity and non-repudiation.
What does the X.509 standard define?
Answer: The format and fields of digital certificates used in PKI
X.509 is the ITU-T standard that specifies the format of public key certificates, including fields such as subject, issuer, validity period, and public key.
Which mechanism allows a relying party to check in real time whether a digital certificate has been revoked?
Answer: Online Certificate Status Protocol (OCSP)
OCSP provides real-time certificate status by querying an OCSP responder, unlike CRLs which are periodically downloaded batch lists.
What is the purpose of key stretching techniques such as PBKDF2 or bcrypt?
Answer: To slow down brute-force and dictionary attacks against passwords
Key stretching algorithms apply many iterations of hashing to a password, making brute-force and dictionary attacks computationally expensive.